CVE-2020-20913: SQL Injection
Published Apr 4, 2023
·Updated
SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basictitle parameter.
Affected Software
1 affected component
Mingsoft MCMS=4.7.2
Event History
Apr 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this SQL Injection vulnerability?
The vulnerability ID for this SQL Injection vulnerability is CVE-2020-20913.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability is Ming-Soft MCMS v.4.7.2.
3
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by executing arbitrary code via the basic_title parameter.
4
What is the severity level of this vulnerability?
The severity level of this vulnerability is critical, with a severity value of 9.8.
5
Is there a fix available for this vulnerability?
It is recommended to update to a patched version of Ming-Soft MCMS to fix this vulnerability. Please refer to the vendor's website or support for more information.